Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-34223 PoC — Human Resource Management System 安全漏洞

Source
Associated Vulnerability
Title:Human Resource Management System 安全漏洞 (CVE-2024-34223)
Description:Human Resource Management System是maverickosama个人开发者的一个人力资源管理系统。 Sourcecodester Human Resource Management System 1.0版本存在安全漏洞,该漏洞源于存在不安全权限。
Description
CVE-2024-34223 | Insecure permission
Readme
# Human Resource Management System Project in PHP and MySQL Free Source Code
#### Submitter: Kha Do

## Vulnerability
Insecure Permission

## Description
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

## Affected component
Path URL: /hrm/leaverequest.php

Parameter: **?msg=**, **?id=**

## Impact
The normal user can self-approve or reject leave ticket, which is not permitted.

**id:** accept ticket.

**msg:** reject ticket.

## PoC

https://github.com/dovankha/CVE-2024-34223/assets/63991630/05efa194-bcc4-4ecf-bf47-8316fae2452a


File Snapshot

[4.0K] /data/pocs/160004e3c0bd48cbbbab585c46089d41fe520b89 └── [ 654] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.